vCenter Appliance fails to join AD domain due to clock skew
search cancel

vCenter Appliance fails to join AD domain due to clock skew

book

Article ID: 373032

calendar_today

Updated On:

Products

VMware vCenter Server 8.0 VMware vCenter Server 7.0 VMware vCenter Server 6.0

Issue/Introduction

vCenter fails to join the domain through GUI or domainjoin-cli with error codes such as:

ldm client exception: Error trying to join AD, error code [31]
Error: ERROR_GEN_FAILURE [code 0x0000001f]

Likewise logging indicates a time skew error during the domain join process:

ERROR lwio: [0x7f2fa54b8640] GSS-API error calling gss_init_sec_context: 100007 (Clock skew too great)

Environment

VMware vCenter Server

Cause

These failures occur when the time on the vCenter Appliance is out of sync with the time on the domain controllers.

Resolution

To resolve the issue, correct the time for the vCenter appliance by configuring an NTP server or setting the time manually, or by setting the time or correcting the NTP settings on the ESXi host that the VCSA is running on if it's set to synchronize time with the host.

Additional Information

Even importing of VMs between the VC nodes fails if there is a time zone difference between the VC nodes. So, both the source & destination VC nodes must be in the same time zone for this purpose.